Back to blog
Buyer Guides

vCISO, consultancy or in-house hire: which one, and when to switch

Three ways to get security leadership, with very different costs, speeds and failure modes. What each is genuinely good at, and the accountability question that decides it.
GRC Copilot Team
vCISO, consultancy or in-house hire: which one, and when to switch

The question is rarely "who is best" — it is "what does this organisation need for the next eighteen months, and what happens after that". All three models work; they fail differently, and the failure modes are predictable enough to plan around.

The three models

Fractional / vCISOConsultancyIn-house hire
Typical useOngoing leadership, part-timeDefined project, fixed scopePermanent capability
Speed to startDays to weeksWeeksTwo to six months to hire
Cost shapeMonthly retainerProject feeSalary + overhead, permanent
BreadthBroad, senior, shallow hoursDeep in their specialismWhatever one person knows
Main failure modeToo few hours to executeLeaves, taking the knowledgeWrong hire is expensive and slow to unwind

When a vCISO fits

Best where you need judgement more than hours: setting direction, choosing frameworks, sizing risk, talking to boards and customers, and supervising people who do the work. Typical fit is a company under a few hundred staff with a real obligation — a certification, a regulator, an enterprise customer — but not enough recurring work to justify a full-time senior salary.

The failure mode is specific and common: a vCISO cannot also be your execution capacity. Two days a month buys direction, not evidence collection, ticket chasing or policy writing. Organisations that buy leadership and expect delivery end up with excellent advice and an unmoved programme.

The fix is to pair the vCISO with either an internal analyst or automation that removes the recurring work. That combination — senior direction plus tooling — is usually cheaper and faster than a full-time hire at the same stage.

Give whoever leads it a system to work in

GRC Copilot carries the control library, evidence and recurring tasks — so fractional leadership spends its hours on decisions instead of chasing spreadsheets.

When a consultancy fits

Best for bounded, expertise-heavy work with a clear end: a first certification where nobody internally knows what "good" looks like, a specific technical assessment, a regulatory response, or surge capacity around an audit.

Two cautions worth stating plainly. First, independence — a firm cannot both implement your management system and certify it, and using the same firm for consulting and audit invites questions even where it is permitted. Second, knowledge transfer: an ISMS built entirely by a consultancy, documented in their templates and understood by nobody internally, tends to fail at the first surveillance visit after they leave. Make handover an explicit deliverable with named internal owners, not an afterthought.

When to hire

Hire when the work is continuous rather than project-shaped, when security is core to your product or your buyers, when a regulator expects an accountable named individual, or when you have enough recurring volume that fractional hours no longer cover it. Questionnaire load and evidence work scale with revenue rather than risk, and that is usually the signal.

The first hire is often better as a capable generalist who will build and operate than as a big-title strategist — direction can be bought fractionally; execution generally cannot.

The question that actually decides it

Accountability cannot be outsourced. Regulators, auditors and customers expect an accountable individual inside your organisation, and contractual or regulatory duties remain yours whoever performs the work.

So the real test is: who inside the company owns the outcome? A vCISO or consultancy can hold the expertise and even the day-to-day, but someone internal must own the risk decisions and be able to answer for them. If nobody can, you have bought activity rather than assurance.

The usual progression

Most companies move through the models rather than choosing one forever: consultancy for the first certification, a vCISO to run the programme afterwards, an internal analyst as evidence and questionnaire volume grows, then a full-time lead once security becomes continuous. Switching is normal and expected — plan the handover points rather than treating each change as a failure of the last arrangement.

Frequently asked questions

How many days a month does a vCISO need?

Commonly two to five, depending on obligations and how much internal execution capacity exists. If you are relying on them to do the work as well as direct it, the number is much higher — or the model is wrong.

Can the same firm consult and audit?

Not for the same management system. Certification bodies must be independent of the implementation, and blurring it undermines the certificate's value.

Is a vCISO acceptable to regulators and customers?

Generally yes, provided accountability is clear and an internal owner exists. Some regulated sectors expect a named, resident individual — check before assuming.

What is the biggest risk with outsourcing?

A programme nobody internally understands. Insist on knowledge transfer, internal control owners, and documentation in your systems rather than the provider's.

Key takeaways

  • Buy judgement fractionally; execution capacity rarely comes with it.
  • Consultancies fit bounded projects — make knowledge transfer a deliverable.
  • Hire when the work becomes continuous, and prefer a builder over a title.
  • Accountability stays internal whatever model you choose.
#vciso #consultancy #hiring #operating-model #accountability #cost